{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/nginx-open-source--1.31.6/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:f5:nginx_open_source:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":6.5,"id":"CVE-2026-90439"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["NGINX Open Source (\u003c 1.31.6)","NGINX Open Source (\u003c= 1.30.5)"],"_cs_severities":["medium"],"_cs_tags":["vulnerability","webserver","dos"],"_cs_type":"advisory","_cs_vendors":["F5"],"content_html":"\u003cp\u003eF5 has published a security bulletin regarding a vulnerability identified in NGINX Open Source, documented as CVE-2026-90439. This vulnerability exposes affected systems to remote denial-of-service (DoS) conditions and potential data integrity compromises. The issue impacts NGINX Open Source versions in the 1.31.x branch prior to 1.31.6, as well as versions up to and including 1.30.5. As NGINX is frequently deployed as a reverse proxy, load balancer, or web server at the perimeter of enterprise environments, the ability for remote, unauthenticated attackers to cause service disruptions or data inconsistencies poses a significant operational and security risk. Defenders should assess their NGINX deployment versions and apply the patches provided by F5 in their security bulletin K000162604 to mitigate the risk of exploitation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an unauthenticated remote attacker to disrupt availability via a denial-of-service attack. Additionally, the vulnerability can lead to data integrity issues within the affected NGINX instance, potentially impacting the reliability of traffic passing through the proxy or the server itself. This could result in service outages and the corruption of data handled by the NGINX software.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAudit all internet-facing and internal NGINX Open Source installations to identify versions 1.31.x (prior to 1.31.6) and versions \u0026lt;= 1.30.5.\u003c/li\u003e\n\u003cli\u003ePatch affected instances immediately by upgrading to the secure versions recommended in F5 security bulletin K000162604.\u003c/li\u003e\n\u003cli\u003eReview NGINX configuration and access logs for anomalous traffic patterns or unexpected service restarts that may indicate attempted exploitation of CVE-2026-90439.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-16T13:06:42Z","date_published":"2026-09-16T13:06:42Z","id":"https://feed.craftedsignal.io/briefs/2026-09-nginx-vulnerability/","summary":"A vulnerability in F5 NGINX, tracked as CVE-2026-90439, allows remote attackers to trigger a denial of service and potentially compromise data integrity.","title":"Vulnerability in F5 NGINX","url":"https://feed.craftedsignal.io/briefs/2026-09-nginx-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - NGINX Open Source (\u003c 1.31.6)","version":"https://jsonfeed.org/version/1.1"}